PoC Index

CVE-2023-5933

MEDIUM 6.4EPSS 0.7%

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.

CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v3.1
6.4 MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
EPSS
0.68% chance of exploitation in the next 30 days, 50th percentile
Published
2024-01-26
Updated
2026-04-25

Proof-of-concept exploits (1)

References

Related